Password-spray throttling bypass tool exploiting a spoofable per-IP rate limiter
The app throttles failed logins per source IP, but reads that IP straight from an X-Forwarded-For header the client fully controls. Rotating a fresh fake value per request turns a 5-attempt lockout into unlimited attempts.
The full write-up is locked
Unlock the step-by-step write-up, screenshots and PoC file by purchasing this listing.
The app throttles failed logins per source IP, but reads that IP straight from an X-Forwarded-For header the client fully controls. Rotating a fresh fake value...…
Browse the file tree freely — unlock to download.
-
spray_header_bypass.py 1.9 KB
Offensive tooling labs
View all labsNo related labs for this topic yet.
Reviews & Questions
Sign in to ask a question or leave a review.
No reviews or questions yet — be the first.
Listing Details
- Author
- x00sec
- Published
- 2026-09-13
- Target / OS
- Login endpoint that rate-limits by client IP taken from X-Forwarded-For
- Category
- Scripts & Tools
- Payout Method
- No preference
Price
0.0170 BTC
≈ $1,105.00
Live Chat
Ask the seller or other buyers a question — mention someone with @handle
No messages yet — start the conversation.
Sign in to join the conversation.